CVE-2001-0155: High severity van dyke technologies vshell vulnerability
Published Jun 2, 2001
·Updated
Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.
Affected Software
1 affected component
Van Dyke Technologies Vshell<=1.0.1
Event History
Jun 2, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0155?
CVE-2001-0155 has a high severity level due to its potential for arbitrary command execution.
2
How do I fix CVE-2001-0155?
To fix CVE-2001-0155, upgrade VShell to version 1.0.2 or later.
3
What are the risks associated with CVE-2001-0155?
The risks associated with CVE-2001-0155 include unauthorized access and remote code execution.
4
Which versions of VShell are affected by CVE-2001-0155?
VShell versions 1.0.1 and earlier are affected by CVE-2001-0155.
5
How does CVE-2001-0155 allow attackers to exploit the system?
CVE-2001-0155 allows attackers to exploit the system by sending a user name with format string specifiers, leading to arbitrary command execution.